I'm not exactly sure what is wrong

Discussion in 'Malware Help (A Specialist Will Reply)' started by enimrac1206, Aug 3, 2013.

  1. enimrac1206

    enimrac1206 Private E-2

    I'm not exactly sure what is wrong but something is wrong. Everything looks like something from an early version of Windows and I keep getting a "Failed to connect to a windows service" and "Receiver.exe - bad image" notification upon reboot. I have attached all of the logs for review. Thanks.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it delete Potential Unwanted Programs.

    Uninstall the below.

    • Self-service Plug-in
    • ShopAtHome.com Helper
    • ShopAtHome.com Toolbar
    • DefaultTab
    • Ask Toolbar

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. enimrac1206

    enimrac1206 Private E-2

    Hit-man says my free license is expired so I can't delete anything. I was able to uninstall the following:

    ShopAtHome.com Helper
    ShopAtHome.com Toolbar
    DefaultTab

    Ask toolbar was not in the programs list for uninstallation so I went to the C:drive location and deleted the folder for it. Where would I find the Self Service plug in?

    I am still getting the following error message upon log in: C:\Windows\system32\WindowsCodecs.dll is either not designed to run on Windows or it contains an error. Try installing the program again using the original installation media or contact your system administrator or the software vendor for support.

    I have attached my MG Tools log
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    All of the below still show as being installed, so I would like for you to use Revo Uninstaller to see if it will detect them and uninstall them.
    • Ask Toolbar
    • Self-service Plug-in
    • ShopAtHome.com Helper

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R3 - URLSearchHook: (no name) - {ece24dcf-8548-4655-b392-47a388721482} - (no file)
    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    • O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    • O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
    • O3 - Toolbar: Somoto Toolbar - {652853ad-5592-4231-88c6-706613a52e61} - C:\Program Files (x86)\somototoolbar\vmntemplateX.dll (file missing)
    • O3 - Toolbar: ShopAtHome.com Toolbar - {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Users\Michelle\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (file missing)
    • O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
    • O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe"

    After clicking Fix exit HJT.


    Delete these
    C:\Program Files (x86)\Common Files\Spigot
    C:\Program Files (x86)\Ask.com


    And if this file is visible, please delete that too:
    C:\Windows\system32\WindowsCodecs.dll
    ...and let me know. :)


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Please save the work in your browsers before proceeding.
    • Double-click JRT.exe to run (Vista/7 right-click and select Run as Administrator)
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Please attach JRT.txt to your next message. (See: HOW TO: Attach Items To Your Post )


    I know it will not remove anything, but re run Hitman again, I want to see what's left.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  5. enimrac1206

    enimrac1206 Private E-2

    There were a few things I couldn't delete. System wouldn't let me. Logs attached.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, this file should not be deleted. WindowsCodecs.dll

    Little bit left to do here and then you may have to go onto the software forum afterwards.


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Users\Michelle\Local Settings\Temp\AskSearch
    C:\Program Files (x86)\Common Files\Spigot
    C:\Program Files (x86)\Ask.com
    
    :reg
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}]
    [-HKU\S-1-5-21-1721611782-460635201-2206628158-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document into a text file and attach it here in your next post.

    Rescan with Hitman again and attach log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  7. enimrac1206

    enimrac1206 Private E-2

    I'm no longer getting the error message upon reboot. Here is the info that you requested and I have attached the logs.

    All processes killed
    ========== FILES ==========
    C:\Users\Michelle\Local Settings\Temp\AskSearch folder moved successfully.
    File/Folder C:\Program Files (x86)\Common Files\Spigot not found.
    File/Folder C:\Program Files (x86)\Ask.com not found.
    ========== REGISTRY ==========
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ not found.
    Registry key HKEY_USERS\S-1-5-21-1721611782-460635201-2206628158-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}\ not found.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Cory
    ->Temp folder emptied: 27728358 bytes
    ->Temporary Internet Files folder emptied: 77678488 bytes
    ->Java cache emptied: 5015603 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Flash cache emptied: 902 bytes

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Michelle
    ->Temp folder emptied: 58875985 bytes
    ->Temporary Internet Files folder emptied: 369679966 bytes
    ->Java cache emptied: 13431877 bytes
    ->Flash cache emptied: 23751 bytes

    User: Public

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 1243666 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 35687208 bytes
    %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 1659658 bytes
    %systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 753 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67758 bytes
    RecycleBin emptied: 1818981 bytes

    Total Files Cleaned = 565.00 mb


    OTM by OldTimer - Version 3.1.21.0 log created on 08052013_202319

    Files moved on Reboot...
    C:\Users\Cory\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    C:\Users\Cory\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\7A7E08C8-3FF5-45F2-873D-A84D669DC82F.dat moved successfully.
    C:\Users\Cory\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P4GBRWHT\like[1].htm moved successfully.
    C:\Users\Cory\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P4GBRWHT\showthread[1].htm moved successfully.
    C:\Users\Cory\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BHIRCQJD\ads[6].htm moved successfully.
    C:\Users\Cory\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5X1GSBRM\s2[5].htm moved successfully.
    C:\Users\Cory\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F7PJN4Z\xd_arbiter[1].htm moved successfully.
    C:\Users\Cory\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\57G8JXV1\xd_arbiter[1].htm moved successfully.
    C:\Users\Cory\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
    C:\Users\Michelle\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    C:\Users\Michelle\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\7A7E08C8-3FF5-45F2-873D-A84D669DC82F.dat moved successfully.
    C:\Users\Michelle\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VHMC0YGN\google_com[2].htm moved successfully.
    C:\Users\Michelle\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
    C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

    Registry entries deleted on Reboot...
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent. The file was deleted, replaced by Windows, and all is well. No junk left to remove either. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. enimrac1206

    enimrac1206 Private E-2

    Thanks so much for your help!!
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds